News Feed
Jobs Feed
Sections

Recent Jobs

News Archive
Secunia.com:
PHP Integer Overflow Vulnerability and Security Bypass
June 01, 2007 @ 11:33:00

Secunia has released an advisory for PHP today related to an issue caused by an integer overflow that could allow for bypassing of security of an application.

A weakness and a vulnerability have been reported in PHP 5, where the vulnerability has unknown impact and the weakness can be exploited by malicious, local users to bypass certain security restrictions.

The issue is caused by issues with the chunk_split and realpath functions that can lead to a bypass of the open_basedir restriction on a server.

The issue is marked as "moderately critical" and it is suggested that users update to PHP 5.2.3 to correct the issue.

0 comments voice your opinion now!
integer overflow vulnerability security bypass openbasedir integer overflow vulnerability security bypass openbasedir



Similar Posts

Gareth Heyes' Blog: Exploiting PHP SELF

PHPro.org: PHP Security

Pierre-Alain Joye's Blog: PHP Security Conference in Paris, 2007/01/29

Ivo Jansch\'s Blog: How a PHP notice revealed a quirk of Norton Internet Security

SitePoint PHP Blog: Evaluating PHP Applications


Community Events







Don't see your event here?
Let us know!


code example PEAR mysql conference book framework release releases developer database ajax security zendframework PHP5 cakephp zend job application package

All content copyright, 2008 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework